This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ads in the corner of every webpage [Solved]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm having a problem where ads are appearing in the bottom left corner of nearly every webpage I visit, nearly all of them linking to ads.yieldmanager.com. I'm also getting the occasional random direct to another webpage - this has only happened a couple of times, but I only really noticed the problem in the last day or so. I've run scans with ad-aware, Avast, Malware Bytes and TDSS Killer, and none of these have found anything. One of the posts in the help section said I should run DDS and paste the log, so here it is - any help is greatly appreciated! DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 9.0.8112.16457 Run by [removed] at 19:57:33 on 2013-01-03 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.44.1033.18.16291.12780 [GMT 0:00] . AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} AV: Lavasoft Ad-Aware *Disabled/Updated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7} SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Lavasoft Ad-Aware *Disabled/Updated* {5BB89C30-6480-BC7C-9F17-199BD76F557A} FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe C:\Windows\system32\taskhost.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\Bluetooth Suite\adminservice.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\IProsetMonitor.exe C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Windows\System32\igfxpers.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Windows\system\ComHookMonitor.exe C:\Program Files\ASUS Xonar D2 Audio\Customapp\ASUSAUDIOCENTER.EXE C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Steam\Steam.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe C:\Users\Icepick\Local Settings\Apps\F.lux\flux.exe C:\Users\Icepick\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe C:\Program Files (x86)\CyberLink\Shared files\brs.exe C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Program Files\iPod\bin\iPodService.exe C:\PROGRA~2\AD-AWA~1\AdAware.exe C:\Program Files (x86)\mIRC\mirc.exe C:\Windows\system32\wuauclt.exe C:\Program Files (x86)\Opera\opera.exe C:\Windows\explorer.exe C:\Program Files (x86)\Ipswitch\WS_FTP 12\WsftpCOMHelper.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . mWinlogon: Userinit = userinit.exe BHO: DivX Plus Web Player HTML5 : {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll BHO: CIESpeechBHO Class: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent uRun: [Power2GoExpress] NA uRun: [NCsoft] mRun: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" mRun: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" mRun: [UpdatePDRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\7.0" mRun: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" mRun: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe mRun: [UpdatePPShortCut] "C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0" mRun: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Blu-ray Disc Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [Ad-Aware Browsing Protection] "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe" mRun: [Ad-Aware Antivirus] "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" –windows-run mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent StartupFolder: C:\Users\Icepick\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Icepick\AppData\Roaming\Dropbox\bin\Dropbox.exe StartupFolder: C:\Users\Icepick\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Trillian.lnk - C:\Program Files (x86)\Trillian\trillian.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:0 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableLUA = dword:0 mPolicies-System: EnableUIADesktopToggle = dword:0 mPolicies-System: PromptOnSecureDesktop = dword:0 IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab TCP: NameServer = 192.168.2.1 TCP: Interfaces\{D0F9571C-7E02-4430-BD61-73454653C404} : DHCPNameServer = 192.168.2.1 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll SSODL: WebCheck - SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll x64-BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe x64-Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" x64-Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" x64-Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" x64-Run: [Cmaudio8788] C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.cpl,CMICtrlWnd x64-Run: [Cmaudio8788Hook] C:\Windows\system\ComHookMonitor.exe x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab x64-DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - x64-Notify: igfxcui - igfxdev.dll x64-SSODL: WebCheck - Hosts: 199.193.118.246 www.google-analytics.com. Hosts: 199.193.118.246 ad-emea.doubleclick.net. Hosts: 199.193.118.246 www.statcounter.com. Hosts: 199.193.118.246 connect.facebook.net. Hosts: 93.115.241.27 www.google-analytics.com. . Note: multiple HOSTS entries found. Please refer to Attach.txt . ============= SERVICES / DRIVERS =============== . R0 gfibto;gfibto;C:\Windows\System32\drivers\gfibto.sys [2013-1-3 14456] R0 mv91cons;Marvell 91xx Config Device Driver;C:\Windows\System32\drivers\mv91cons.sys [2011-3-14 24880] R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-1-3 984144] R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-1-3 370288] R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2011/09/10 19:34:34];C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [2010-2-24 146928] R2 Ad-Aware Service;Ad-Aware Service;C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [2012-12-14 1236968] R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-1-3 25232] R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-1-3 71600] R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2011-3-13 74912] R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-1-3 44808] R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;C:\Windows\System32\IPROSetMonitor.exe [2011-8-21 164520] R2 SBAMSvc;Ad-Aware;C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [2012-9-20 3677000] R2 sbapifs;sbapifs;C:\Windows\System32\drivers\sbapifs.sys [2012-9-12 82872] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-2 382824] R3 AthBTPort;Atheros Virtual Bluetooth Class;C:\Windows\System32\drivers\btath_flt.sys [2011-3-13 36000] R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\System32\drivers\btath_a2dp.sys [2011-3-13 298656] R3 BTATH_BUS;Atheros Bluetooth Bus;C:\Windows\System32\drivers\btath_bus.sys [2011-3-13 28832] R3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\System32\drivers\btath_hcrp.sys [2011-3-13 201376] R3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\System32\drivers\btath_lwflt.sys [2011-3-13 55456] R3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\System32\drivers\btath_rcp.sys [2011-3-13 154272] R3 BtFilter;BtFilter;C:\Windows\System32\drivers\btfilter.sys [2011-3-13 280224] R3 cmudaxp;ASUS Xonar D2 Audio Interface;C:\Windows\System32\drivers\cmudaxp.sys [2011-9-10 1161216] R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-8-21 317440] R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-12-10 80384] R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-12-10 181248] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-8-21 452200] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-9 160944] S3 ATHDFU;Atheros Valkyrie USB BootROM;C:\Windows\System32\drivers\AthDfu.sys [2011-3-13 51872] S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-21 20992] S3 Synth3dVsc;Synth3dVsc;C:\Windows\System32\drivers\Synth3dVsc.sys [2010-11-21 88960] S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\System32\drivers\terminpt.sys [2010-11-21 34816] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232] S3 tsusbhub;tsusbhub;C:\Windows\System32\drivers\tsusbhub.sys [2010-11-21 117248] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-5-10 51712] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-8-22 1255736] . =============== Created Last 30 ================ . 2013-01-03 19:36:09 ——– d—–w- C:\Users\Icepick\AppData\Roaming\Malwarebytes 2013-01-03 19:36:00 ——– d—–w- C:\ProgramData\Malwarebytes 2013-01-03 19:35:59 24176 —-a-w- C:\Windows\System32\drivers\mbam.sys 2013-01-03 19:35:59 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-01-03 19:32:48 ——– d—–w- C:\Users\Icepick\AppData\Local\Programs 2013-01-03 18:58:19 ——– d—–w- C:\ProgramData\Ad-Aware Antivirus 2013-01-03 18:57:08 ——– d—–w- C:\Users\Icepick\AppData\Roaming\LavasoftStatistics 2013-01-03 18:49:03 984144 —-a-w- C:\Windows\System32\drivers\aswSnx.sys 2013-01-03 18:49:03 71600 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys 2013-01-03 18:49:03 54072 —-a-w- C:\Windows\System32\drivers\aswRdr2.sys 2013-01-03 18:48:56 41224 —-a-w- C:\Windows\avastSS.scr 2013-01-03 18:48:49 ——– d—–w- C:\ProgramData\AVAST Software 2013-01-03 18:48:49 ——– d—–w- C:\Program Files\AVAST Software 2013-01-03 18:46:19 ——– d—–w- C:\Program Files (x86)\Ad-Aware Antivirus 2013-01-03 18:46:12 ——– d—–w- C:\Users\Icepick\AppData\Local\Downloaded Installations 2013-01-03 18:46:11 47496 —-a-w- C:\Windows\System32\sbbd.exe 2013-01-03 18:46:11 14456 —-a-w- C:\Windows\System32\drivers\gfibto.sys 2013-01-03 18:44:12 ——– d—–w- C:\ProgramData\blekko toolbars 2013-01-03 18:44:10 ——– d—–w- C:\Users\Icepick\AppData\Local\adawarebp 2013-01-03 18:44:09 ——– d—–w- C:\ProgramData\Ad-Aware Browsing Protection 2013-01-03 18:44:06 ——– d—–w- C:\Program Files (x86)\adawaretb 2013-01-03 18:44:04 ——– d—–w- C:\Program Files (x86)\Toolbar Cleaner 2013-01-03 18:42:44 ——– d—–w- C:\Users\Icepick\AppData\Roaming\Ad-Aware Antivirus 2013-01-02 00:35:30 9125352 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3B7422F6-4D7E-41B6-849D-4D72FAB6237F}\mpengine.dll 2013-01-01 20:24:26 ——– d—–w- C:\Users\Icepick\AppData\Local\{79FAF880-46D9-426D-B103-6ED5D1144571} 2012-12-27 19:43:00 ——– d—–w- C:\Users\Icepick\AppData\Local\{72E822EA-14AE-48EF-BBD7-739828CDBFBC} 2012-12-22 03:01:18 46080 —-a-w- C:\Windows\System32\atmlib.dll 2012-12-22 03:01:18 367616 —-a-w- C:\Windows\System32\atmfd.dll 2012-12-22 03:01:18 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2012-12-22 03:01:18 295424 —-a-w- C:\Windows\SysWow64\atmfd.dll 2012-12-20 09:55:16 ——– d—–w- C:\Users\Icepick\AppData\Local\{EDC34CD7-74EE-4BFB-B1D5-AF52CBDBA8BA} 2012-12-16 20:44:36 ——– d—–w- C:\Users\Icepick\AppData\Local\{7398B953-2964-49FA-83B4-849A40214C52} 2012-12-13 18:22:28 ——– d—–w- C:\Users\Icepick\AppData\Local\{8CC2E226-FC02-48EC-9264-D518621FAF71} 2012-12-13 09:28:59 887296 —-a-w- C:\Program Files\Internet Explorer\iedvtool.dll 2012-12-13 09:28:59 678912 —-a-w- C:\Program Files (x86)\Internet Explorer\iedvtool.dll 2012-12-13 09:28:59 499200 —-a-w- C:\Program Files\Internet Explorer\jsdbgui.dll 2012-12-13 09:28:59 387584 —-a-w- C:\Program Files (x86)\Internet Explorer\jsdbgui.dll 2012-12-11 21:04:14 33240 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys 2012-12-11 21:04:11 ——– d—–w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2012-12-11 21:04:11 ——– d—–w- C:\Program Files\iTunes 2012-12-11 21:04:11 ——– d—–w- C:\Program Files\iPod 2012-12-11 21:04:11 ——– d—–w- C:\Program Files (x86)\iTunes 2012-12-09 17:01:48 ——– d—–w- C:\Users\Icepick\AppData\Local\{00AC25ED-9CE8-4003-8C63-8AAC179367A7} 2012-12-09 16:55:58 ——– d—–w- C:\Users\Icepick\AppData\Roaming\ftblauncher 2012-12-09 00:08:54 ——– d—–w- C:\Users\Icepick\AppData\Local\{A953133B-1B2D-47EA-9CDC-A783DABB54A2} 2012-12-06 17:15:45 ——– d—–w- C:\Users\Icepick\AppData\Local\{6F64AC04-860D-4AF8-B4A0-B9814859F729} 2012-12-05 22:44:48 ——– d—–w- C:\Users\Icepick\AppData\Local\{EC0ABABE-7D5E-4DFF-AAF2-FBC9D73149DC} 2012-12-04 22:17:55 ——– d—–w- C:\Users\Icepick\AppData\Local\{AD34F7C5-E8FA-4D68-9AF7-DD6330763C34} . ==================== Find3M ==================== . 2012-12-12 00:05:32 73656 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-12-12 00:05:32 697272 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-11-22 03:26:40 3149824 —-a-w- C:\Windows\System32\win32k.sys 2012-11-14 06:11:44 2312704 —-a-w- C:\Windows\System32\jscript9.dll 2012-11-14 06:04:11 1392128 —-a-w- C:\Windows\System32\wininet.dll 2012-11-14 06:02:49 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl 2012-11-14 05:57:46 599040 —-a-w- C:\Windows\System32\vbscript.dll 2012-11-14 05:57:35 173056 —-a-w- C:\Windows\System32\ieUnatt.exe 2012-11-14 05:52:40 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2012-11-14 02:09:22 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll 2012-11-14 01:58:15 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2012-11-14 01:57:37 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll 2012-11-14 01:49:25 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe 2012-11-14 01:48:27 420864 —-a-w- C:\Windows\SysWow64\vbscript.dll 2012-11-14 01:44:42 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2012-11-13 20:29:04 354216 —-a-w- C:\Windows\SysWow64\DivXControlPanelApplet.cpl 2012-11-09 05:45:09 2048 —-a-w- C:\Windows\System32\tzres.dll 2012-11-09 04:42:49 2048 —-a-w- C:\Windows\SysWow64\tzres.dll 2012-11-02 05:59:11 478208 —-a-w- C:\Windows\System32\dpnet.dll 2012-11-02 05:11:31 376832 —-a-w- C:\Windows\SysWow64\dpnet.dll 2012-10-25 03:12:26 94208 —-a-w- C:\Windows\SysWow64\QuickTimeVR.qtx 2012-10-25 03:12:26 69632 —-a-w- C:\Windows\SysWow64\QuickTime.qts 2012-10-16 08:38:37 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll 2012-10-16 08:38:34 350208 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll 2012-10-16 07:39:52 561664 —-a-w- C:\Windows\apppatch\AcLayers.dll 2012-10-10 21:22:54 2428776 —-a-w- C:\Windows\SysWow64\nvapi.dll 2012-10-10 21:22:52 26331496 —-a-w- C:\Windows\System32\nvoglv64.dll 2012-10-10 21:22:52 1760104 —-a-w- C:\Windows\System32\nvdispco64.dll 2012-10-10 21:22:32 15309160 —-a-w- C:\Windows\SysWow64\nvd3dum.dll 2012-10-10 21:22:26 2747240 —-a-w- C:\Windows\System32\nvcuvid.dll 2012-10-10 21:22:24 19906920 —-a-w- C:\Windows\SysWow64\nvoglv32.dll 2012-10-10 21:22:18 13443944 —-a-w- C:\Windows\System32\drivers\nvlddmkm.sys 2012-10-10 21:22:14 17559912 —-a-w- C:\Windows\SysWow64\nvcompiler.dll 2012-10-09 18:17:13 55296 —-a-w- C:\Windows\System32\dhcpcsvc6.dll 2012-10-09 18:17:13 226816 —-a-w- C:\Windows\System32\dhcpcore6.dll 2012-10-09 17:40:31 44032 —-a-w- C:\Windows\SysWow64\dhcpcsvc6.dll 2012-10-09 17:40:31 193536 —-a-w- C:\Windows\SysWow64\dhcpcore6.dll . ============= FINISH: 19:57:42.85 ===============
Hi and Welcome!! My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Having said that….Let's get going!!
———-

[external image: Posted Image] Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

[external image: Posted Image] AdwCleaner
  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • You will be prompted to restart your computer. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
———-
I seem to be having a problem with aswMBR - it runs for a minute or two, scanning through my directory structure before it hits C:\Users\Icepick\AppData\Local\Microsoft\Windows Live\Installer\Catalog I left it for about 15 minutes but it never moved on from this dir, and it only has 5 files in it totalling about 2mb. I ran it twice, with the same effect both times. I've got the log from what it did, but I don't know how useful that will be since I'm guessing it didn't finish. Any idea how I can get it moving? aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2013-01-03 22:47:22 —————————– 22:47:22.060 OS Version: Windows x64 6.1.7601 Service Pack 1 22:47:22.060 Number of processors: 8 586 0x2A07 22:47:22.061 ComputerName: LAMORA UserName: 22:47:22.724 Initialize success 22:47:22.783 AVAST engine defs: 13010300 22:47:25.160 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 22:47:25.163 Disk 0 Vendor: WDC_WD10EALS-00Z8A0 05.01D05 Size: 953869MB BusType: 11 22:47:25.167 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T0L0-1 22:47:25.170 Disk 1 Vendor: KINGSTON_SH100S3240G 320ABBF0 Size: 228936MB BusType: 11 22:47:25.277 Disk 1 MBR read successfully 22:47:25.281 Disk 1 MBR scan 22:47:25.285 Disk 1 Windows 7 default MBR code 22:47:25.289 Disk 1 Partition 1 00 07 HPFS/NTFS NTFS 228934 MB offset 2048 22:47:25.323 Disk 1 scanning C:\Windows\system32\drivers 22:47:31.692 Service scanning 22:47:34.349 Modules scanning 22:47:34.358 Disk 1 trace - called modules: 22:47:34.371 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys 22:47:34.378 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0xfffffa800d2ee060] 22:47:34.383 3 CLASSPNP.SYS[fffff8800185a43f] -> nt!IofCallDriver -> [0xfffffa800cf81790] 22:47:34.388 5 ACPI.sys[fffff88000f567a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0xfffffa800d00e060] 22:47:34.988 AVAST engine scan C:\Windows 22:47:40.671 AVAST engine scan C:\Windows\system32 22:49:39.417 AVAST engine scan C:\Windows\system32\drivers 22:49:55.194 AVAST engine scan C:\Users\Icepick 23:08:32.308 Disk 1 MBR has been saved successfully to "C:\Users\Icepick\Desktop\MBR.dat" 23:08:32.312 The log file has been saved successfully to "C:\Users\Icepick\Desktop\aswMBR.txt" AdwCleaner seemed to work correctly, though, so here is the log from that. # AdwCleaner v2.104 - Logfile created 01/03/2013 at 23:17:02 # Updated 29/12/2012 by Xplode # Operating system : Windows 7 Ultimate Service Pack 1 (64 bits) # User : Icepick - LAMORA # Boot Mode : Normal # Running from : C:\Users\Icepick\Desktop\AdwCleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Program Files (x86)\adawaretb Folder Deleted : C:\ProgramData\blekko toolbars Folder Deleted : C:\Users\Icepick\AppData\LocalLow\adawaretb ***** [Registry] ***** ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16457 [OK] Registry is clean. -\\ Opera v12.12.1707.0 File : C:\Users\Icepick\AppData\Roaming\Opera\Opera\operaprefs.ini [OK] File is clean. ************************* AdwCleaner[S1].txt - [795 octets] - [03/01/2013 23:17:02] ########## EOF - C:\AdwCleaner[S1].txt - [854 octets] ##########
Hi,

That log looks fine….

ComboFix

Download Combofix from the link below, and save it to your desktop.
Link

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-
Here is the log from ComboFix. I'm in the UK so I'm off to bed now - will probably be 18 hours or so before I can reply again. Thanks for your help so far! ComboFix 13-01-03.05 - Icepick 04/01/2013 0:38.1.8 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.44.1033.18.16291.13005 [GMT 0:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} AV: Lavasoft Ad-Aware *Disabled/Updated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7} FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC} SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Lavasoft Ad-Aware *Disabled/Updated* {5BB89C30-6480-BC7C-9F17-199BD76F557A} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Icepick\AppData\Local\assembly\tmp c:\windows\SysWow64\tmpAA79.tmp D:\install.exe . . ((((((((((((((((((((((((( Files Created from 2012-12-04 to 2013-01-04 ))))))))))))))))))))))))))))))) . . 2013-01-04 00:42 . 2013-01-04 00:42 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2013-01-04 00:42 . 2013-01-04 00:42 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-01-03 19:58 . 2012-12-17 06:43 38096 —-a-w- c:\windows\system32\drivers\gfiark.sys 2013-01-03 19:36 . 2013-01-03 19:36 ——– d—–w- c:\users\Icepick\AppData\Roaming\Malwarebytes 2013-01-03 19:36 . 2013-01-03 19:36 ——– d—–w- c:\programdata\Malwarebytes 2013-01-03 19:35 . 2013-01-03 19:36 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-01-03 19:35 . 2012-12-14 16:49 24176 —-a-w- c:\windows\system32\drivers\mbam.sys 2013-01-03 19:32 . 2013-01-03 19:32 ——– d—–w- c:\users\Icepick\AppData\Local\Programs 2013-01-03 18:58 . 2013-01-03 18:58 ——– d—–w- c:\programdata\Ad-Aware Antivirus 2013-01-03 18:57 . 2013-01-03 18:57 ——– d—–w- c:\users\Icepick\AppData\Roaming\LavasoftStatistics 2013-01-03 18:49 . 2012-10-30 22:51 59728 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2013-01-03 18:49 . 2012-10-30 22:51 984144 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2013-01-03 18:49 . 2012-10-30 22:51 71600 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-01-03 18:49 . 2012-10-30 22:51 370288 —-a-w- c:\windows\system32\drivers\aswSP.sys 2013-01-03 18:49 . 2012-10-30 22:51 25232 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-01-03 18:49 . 2012-10-30 22:50 285328 —-a-w- c:\windows\system32\aswBoot.exe 2013-01-03 18:49 . 2012-10-15 16:59 54072 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-01-03 18:48 . 2012-10-30 22:51 41224 —-a-w- c:\windows\avastSS.scr 2013-01-03 18:48 . 2012-10-30 22:50 227648 —-a-w- c:\windows\SysWow64\aswBoot.exe 2013-01-03 18:48 . 2013-01-03 18:48 ——– d—–w- c:\programdata\AVAST Software 2013-01-03 18:48 . 2013-01-03 18:48 ——– d—–w- c:\program files\AVAST Software 2013-01-03 18:46 . 2013-01-03 19:58 ——– d—–w- c:\program files (x86)\Ad-Aware Antivirus 2013-01-03 18:46 . 2013-01-03 18:46 ——– d—–w- c:\programdata\Lavasoft 2013-01-03 18:46 . 2013-01-03 18:46 ——– d—–w- c:\users\Icepick\AppData\Local\Downloaded Installations 2013-01-03 18:46 . 2013-01-03 18:46 14456 —-a-w- c:\windows\system32\drivers\gfibto.sys 2013-01-03 18:46 . 2012-09-20 05:40 47496 —-a-w- c:\windows\system32\sbbd.exe 2013-01-03 18:44 . 2013-01-03 18:44 ——– d—–w- c:\users\Icepick\AppData\Local\adawarebp 2013-01-03 18:44 . 2013-01-03 18:44 ——– d—–w- c:\programdata\Ad-Aware Browsing Protection 2013-01-03 18:44 . 2013-01-03 18:44 ——– d—–w- c:\program files (x86)\Toolbar Cleaner 2013-01-03 18:42 . 2013-01-04 00:31 ——– d—–w- c:\users\Icepick\AppData\Roaming\Ad-Aware Antivirus 2013-01-02 00:35 . 2012-11-08 17:24 9125352 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3B7422F6-4D7E-41B6-849D-4D72FAB6237F}\mpengine.dll 2012-12-22 03:01 . 2012-12-16 17:11 46080 —-a-w- c:\windows\system32\atmlib.dll 2012-12-22 03:01 . 2012-12-16 14:45 367616 —-a-w- c:\windows\system32\atmfd.dll 2012-12-22 03:01 . 2012-12-16 14:13 295424 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-22 03:01 . 2012-12-16 14:13 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-13 09:28 . 2012-11-14 06:06 887296 —-a-w- c:\program files\Internet Explorer\iedvtool.dll 2012-12-13 09:28 . 2012-11-14 06:06 499200 —-a-w- c:\program files\Internet Explorer\jsdbgui.dll 2012-12-13 09:28 . 2012-11-14 05:55 2144768 —-a-w- c:\windows\system32\iertutil.dll 2012-12-13 09:28 . 2012-11-14 02:01 678912 —-a-w- c:\program files (x86)\Internet Explorer\iedvtool.dll 2012-12-13 09:28 . 2012-11-14 02:00 387584 —-a-w- c:\program files (x86)\Internet Explorer\jsdbgui.dll 2012-12-13 09:28 . 2012-11-14 07:06 17811968 —-a-w- c:\windows\system32\mshtml.dll 2012-12-13 09:28 . 2012-11-14 06:32 10925568 —-a-w- c:\windows\system32\ieframe.dll 2012-12-11 21:04 . 2012-08-21 13:01 33240 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-12-11 21:04 . 2012-12-11 21:04 ——– d—–w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2012-12-11 21:04 . 2012-12-11 21:04 ——– d—–w- c:\program files\iTunes 2012-12-11 21:04 . 2012-12-11 21:04 ——– d—–w- c:\program files (x86)\iTunes 2012-12-11 21:04 . 2012-12-11 21:04 ——– d—–w- c:\program files\iPod 2012-12-11 20:59 . 2012-12-11 20:59 ——– d—–w- c:\program files (x86)\QuickTime 2012-12-09 16:55 . 2013-01-01 12:53 ——– d—–w- c:\users\Icepick\AppData\Roaming\ftblauncher . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-12-12 00:05 . 2012-03-30 16:28 697272 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-12-12 00:05 . 2011-08-21 20:03 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-11-13 20:29 . 2012-11-13 20:29 354216 —-a-w- c:\windows\SysWow64\DivXControlPanelApplet.cpl 2012-10-25 03:12 . 2012-10-25 03:12 94208 —-a-w- c:\windows\SysWow64\QuickTimeVR.qtx 2012-10-25 03:12 . 2012-10-25 03:12 69632 —-a-w- c:\windows\SysWow64\QuickTime.qts 2012-10-16 08:38 . 2012-11-28 09:12 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2012-10-16 08:38 . 2012-11-28 09:12 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2012-10-16 07:39 . 2012-11-28 09:12 561664 —-a-w- c:\windows\apppatch\AcLayers.dll 2012-10-10 21:23 . 2012-10-10 21:23 247144 —-a-w- c:\windows\system32\nvinitx.dll 2012-10-10 21:23 . 2012-10-10 21:23 1867112 —-a-w- c:\windows\SysWow64\nvcuvenc.dll 2012-10-10 21:23 . 2012-10-10 21:23 18252136 —-a-w- c:\windows\system32\nvd3dumx.dll 2012-10-10 21:23 . 2012-10-10 21:23 1482600 —-a-w- c:\windows\system32\nvdispgenco64.dll 2012-10-10 21:23 . 2012-10-10 21:23 6127464 —-a-w- c:\windows\SysWow64\nvopencl.dll 2012-10-10 21:23 . 2012-10-10 21:23 2574696 —-a-w- c:\windows\SysWow64\nvcuvid.dll 2012-10-10 21:23 . 2012-10-10 21:23 25256296 —-a-w- c:\windows\system32\nvcompiler.dll 2012-10-10 21:23 . 2012-10-10 21:23 831848 —-a-w- c:\windows\SysWow64\nvumdshim.dll 2012-10-10 21:23 . 2012-10-10 21:23 202600 —-a-w- c:\windows\SysWow64\nvinit.dll 2012-10-10 21:23 . 2012-10-10 21:23 7414632 —-a-w- c:\windows\system32\nvopencl.dll 2012-10-10 21:23 . 2012-10-10 21:23 2731880 —-a-w- c:\windows\system32\nvapi64.dll 2012-10-10 21:23 . 2012-10-10 21:23 973672 —-a-w- c:\windows\system32\nvumdshimx.dll 2012-10-10 21:23 . 2012-10-10 21:23 14922600 —-a-w- c:\windows\system32\nvwgf2umx.dll 2012-10-10 21:23 . 2012-10-10 21:23 9146728 —-a-w- c:\windows\system32\nvcuda.dll 2012-10-10 21:23 . 2012-10-10 21:23 7697768 —-a-w- c:\windows\SysWow64\nvcuda.dll 2012-10-10 21:23 . 2012-10-10 21:23 2218344 —-a-w- c:\windows\system32\nvcuvenc.dll 2012-10-10 21:23 . 2012-10-10 21:23 12501352 —-a-w- c:\windows\SysWow64\nvwgf2um.dll 2012-10-10 21:22 . 2012-10-10 21:22 2428776 —-a-w- c:\windows\SysWow64\nvapi.dll 2012-10-10 21:22 . 2012-10-10 21:22 26331496 —-a-w- c:\windows\system32\nvoglv64.dll 2012-10-10 21:22 . 2011-08-21 17:56 1760104 —-a-w- c:\windows\system32\nvdispco64.dll 2012-10-10 21:22 . 2012-10-10 21:22 15309160 —-a-w- c:\windows\SysWow64\nvd3dum.dll 2012-10-10 21:22 . 2012-10-10 21:22 2747240 —-a-w- c:\windows\system32\nvcuvid.dll 2012-10-10 21:22 . 2012-10-10 21:22 19906920 —-a-w- c:\windows\SysWow64\nvoglv32.dll 2012-10-10 21:22 . 2012-10-10 21:22 13443944 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys 2012-10-10 21:22 . 2012-10-10 21:22 17559912 —-a-w- c:\windows\SysWow64\nvcompiler.dll 2012-10-09 18:17 . 2012-11-14 20:44 55296 —-a-w- c:\windows\system32\dhcpcsvc6.dll 2012-10-09 18:17 . 2012-11-14 20:44 226816 —-a-w- c:\windows\system32\dhcpcore6.dll 2012-10-09 17:40 . 2012-11-14 20:44 44032 —-a-w- c:\windows\SysWow64\dhcpcsvc6.dll 2012-10-09 17:40 . 2012-11-14 20:44 193536 —-a-w- c:\windows\SysWow64\dhcpcore6.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 129272 —-a-w- c:\users\Icepick\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 129272 —-a-w- c:\users\Icepick\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 129272 —-a-w- c:\users\Icepick\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 129272 —-a-w- c:\users\Icepick\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Power2GoExpress"="NA" [X] "Steam"="c:\program files (x86)\Steam\steam.exe" [2012-12-04 1354736] "Spotify Web Helper"="c:\program files (x86)\Spotify\Data\SpotifyWebHelper.exe" [2012-11-26 1199576] "F.lux"="c:\users\Icepick\Local Settings\Apps\F.lux\flux.exe" [2009-08-29 966656] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-11-09 17877168] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Ad-Aware Antivirus"="c:\program files (x86)\Ad-Aware Antivirus\AdAwareLauncher –windows-run" [X] "JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-09-07 43608] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2009-11-02 103720] "UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504] "UpdatePDRShortCut"="c:\program files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504] "RemoteControl9"="c:\program files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [2009-07-06 87336] "BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2010-02-24 75048] "UpdatePPShortCut"="c:\program files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504] "UpdatePSTShortCut"="c:\program files (x86)\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe" [2010-05-17 222504] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2012-11-01 1263512] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-11-29 151952] "Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2012-12-11 542104] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136] . c:\users\Icepick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Icepick\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-12-22 28538560] Trillian.lnk - c:\program files (x86)\Trillian\trillian.exe [2012-9-4 2429904] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux3"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service] @="Ad-Aware Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc] @="Service" . R2 Ad-Aware Service;Ad-Aware Service;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe [2012-12-14 1236968] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 SBAMSvc;Ad-Aware;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [2012-09-20 3677000] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944] R3 ATHDFU;Atheros Valkyrie USB BootROM;c:\windows\system32\Drivers\AthDfu.sys [2011-03-13 51872] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168] R3 gfiark;gfiark;c:\windows\system32\drivers\gfiark.sys [2012-12-17 38096] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-21 20992] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-21 88960] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 34816] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 117248] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-08-22 1255736] S0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys [2013-01-03 14456] S0 mv91cons;Marvell 91xx Config Device Driver;c:\windows\system32\DRIVERS\mv91cons.sys [2011-03-14 24880] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2011/09/10 19:34];c:\program files (x86)\CyberLink\PowerDVD9\000.fcl [2010-02-24 10:14 146928] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600] S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe [2011-03-13 74912] S2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe [2011-01-17 164520] S2 sbapifs;sbapifs;c:\windows\system32\DRIVERS\sbapifs.sys [2012-09-12 82872] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824] S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [2011-03-13 36000] S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [2011-03-13 298656] S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [2011-03-13 28832] S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [2011-03-13 201376] S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [2011-03-13 55456] S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [2011-03-13 154272] S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [2011-03-13 280224] S3 cmudaxp;ASUS Xonar D2 Audio Interface;c:\windows\system32\drivers\cmudaxp.sys [2007-09-11 1161216] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-12-10 80384] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-12-10 181248] S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2011-08-01 45416] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-03-21 452200] . . — Other Services/Drivers In Memory — . *Deregistered* - aswMBR . Contents of the 'Scheduled Tasks' folder . 2013-01-04 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 00:05] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-10-30 22:50 133400 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Icepick\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Icepick\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Icepick\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Icepick\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-19 11613288] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-20 168216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-20 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-20 416024] "AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-03-13 617120] "AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-03-13 379552] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032] "Cmaudio8788"="c:\windows\Syswow64\cmicnfgp.cpl" [2007-03-28 6103040] "Cmaudio8788Hook"="c:\windows\system\ComHookMonitor.exe" [2007-06-21 20480] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.2.1 . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKCU-Run-NCsoft - (no file) SafeBoot-62682816.sys . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{B154377D-700F-42cc-9474-23858FBDF4BD}] "ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD9\000.fcl" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-2502402618-3536751710-97130143-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-2502402618-3536751710-97130143-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-01-04 00:44:07 ComboFix-quarantined-files.txt 2013-01-04 00:44 . Pre-Run: 22,814,584,832 bytes free Post-Run: 25,654,865,920 bytes free . - - End Of File - - 74AA6E41DCEF72436217F47ED0860982

Yeah, that seems to have fixed the problem!
Thanks a lot man, I really appreciate the help

Great to hear! Let's get some updates and check for anything else hiding in there before you go. :)
———

[external image: Posted Image] Java

Please go to Start > Control Panel > Programs and Features > uninstall all the Java Programs you see, now download the latest Java from the following link and install it:

http://java.com/en/download/index.jsp
———-

See this page for instructions on how to clear java's cache.

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Installed Applications and Applets
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.
———-

[external image: Posted Image] Malwarebytes

Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

ESET Online Scanner

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
———-
Oops, sorry, didn't notice you had replied, just saw the notification email! Anyway no I think everything is good now, I haven't noticed any more odd behaviour, and I'm *usually* pretty careful when it comes to this stuff (seriously, I honestly have no idea where I picked this thing up from in the first place). Thanks for your help though, much appreciated!
Great!! :thumbup:

Providing there are no other malware related problems…

IT APPEARS THAT YOUR LOGS ARE NOW CLEAN :D SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!! :D

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
———-

The following will implement some cleanup procedures as well as reset System Restore points:

Press the Windows key + R and this will open the Run text box. Copy/paste the following text into the Run box as shown and click OK.
Combofix /Uninstall
(Note: There is a space between the ..X and the /U that needs to be there.)

[external image: Posted Image]
———-

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop. If you did not have Malwarebytes Antimalware before, I would keep it and run it weekly.
———-

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. FireFox If you use Firefox, I recommend installing the following add-ons to help make your Firefox browser more secure:
NoScript
AdBlock Plus

3. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. **There are firewalls that could be downloaded and used but I would personally only recommend using one of the following two below:
Online Armor Free
Agnitum Outpost Firewall Free

5. Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

6. WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

7. Finally, I strongly recommend that you read Miekiemoes' great advice How to prevent malware.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI